4 ms·
Wouldn’t you just remove them from the org?
by booi 2y ago
Wouldn’t you just remove them from the org?
- onionisafruit 2y agoThey may decide to change their github login to <company_name>LIES, and suddenly that’s all over your old PRs and Issues. Including in public repos where customers go looking for help.
- TheDong 2y agoThat's even more true with a dedicated work github account than a mixed personal/work one; either way they can still login and edit the account name even if removed from the company org, and if it's not shared it doesn't burn their personal account too... right? Is this speaking from experience?
- deleted 2y ago[deleted]
- wlesieutre 2y agoWith a dedicated work account the organization can always take over the account (via reset email if need be, since they own your work email account) and do whatever they want with it
- rendaw 2y agoA dedicated work account _where you use your work email address_... that was the missing part throughout this thread. But then if you do that you also lose all your open source work history, which is important from a hiring/resume perspective.
- cdogl 2y agoOne option for those so inclined is to cryptographically sign commits with a key that lists both work and personal email address (assuming your enterprise’s policy allows it). The employer retains control but you have a claim to credit for your work.
- tsimionescu 2y agoIf we're discussing companies willing to go to lengths to scrub you from their GitHub history, they can still replace all commits you've signed with new commits. You likely have no legal rights to that work, and git does allow you to rewrite history arbitrarily.
- shiomiru 2y ago> git does allow you to rewrite history arbitrarily. Technically yes, but the price is too great - everybody who has cloned the repos will now have to nuke their local copies too.
- tsimionescu 2y agoSure, but the same is true for unsigned commits as well, isn't it? Or can you modify the commit metadata without changing the commit hash in those cases?
- shiomiru 2y ago> Sure, but the same is true for unsigned commits as well, isn't it? Yes, I think so. As I understand, GP's idea was to sign your commits proactively.
- tsimionescu 2y agoMy question was, is signing the commits really useful? Isn't it just as hard or easy to scrub you from the repo history regardless of whether the commits are signed or not?
- withinboredom 2y agoIt depends on the jurisdiction. In the US, copyright assignment is usually permanent. In the EU and Canada, you can claw back your rights to a degree and even revoke the usage altogether, if you manage to claw it back because they did "evil" things with it (moral rights). In some cases (even in the US), if the employer does something that would be considered a "breach of contract", you can force them to remove all your code as well. So, it would not be in the company's best interest to scrub their git history.
- connicpu 2y agoIf a spiteful ex-employer wants to scrub ex-employee authorship from the entire commit history in their public repos when someone leaves I don't think there's anything you could do to stop that either way, though it seems like it would be more trouble than it's worth and likely wouldn't scale. If they don't do that, assuming your old company email address still has your name in it I don't see why you'd lose credit for the work you did.
- OJFord 2y agoAnd you could still just change it right, as long as you did so before the employer revoked your access via the work email address.